Metal Seed Backup Ranking Atlas

Final scoring, ranking, and deep-dive analysis of metal seed backup artifacts under a maximalist “artifact purity + physical survivability + minimal failure surface” model. Links are embedded inline in every relevant section (no link dump).

10 devices scored 7 criteria weighted 0–100 per criterion Composite weighted sum Stress-test backbone: Lopp’s metal seed storage reviews

Method: criteria, weights, scoring rules

Scoring scale
0–100
Higher is better; scores reflect the artifact, not purchasing opsec.
Composite formula
Σ(score × weight)
Weights below sum to 100%.

Primary backbone (public destructive tests)

The durability baseline is anchored to Jameson Lopp’s multi-round destructive testing (heat, corrosion, crush) and the consolidated device table and reviews: jlopp.github.io/metal-bitcoin-storage-reviews. For historical context and the “Seedplate from Coinkite” cohort, see: Stress Test Round IV and for Keystone Tablet variants: Stress Test Round V.

Bias uplift rule (explicit): Devices that avoid all three structural metadata hazards receive a scoring advantage: (1) uniquely numbered seals/covers, (2) included tamper-sticker systems as a primary feature, and (3) descriptors/fingerprints/QR embedded into the intended backup artifact. In this set, the “clean plate” cluster best matches that rule.

Criteria & weights (fixed)

Criterion Weight What increases the score What decreases the score
Artifact Metadata & Privacy 30% Plain, un-numbered, minimally branded plates; no enforced seals; no QR/descriptor fields on the metal. Unique serial numbers, numbered seals/covers, seed-name fields, collectible engravings, QR/descriptor on-plate.
Physical Robustness 25% Demonstrated survival under heat/corrosion/crush (preferably in Lopp tests), thick stainless or titanium, readable after stress. Known weak modes (e.g., tile loss in heat, enclosure failure under crush), untested complex mechanisms.
Mechanical Simplicity 15% Single solid plate; minimal fasteners; no tiles/rails; nothing that jams or scatters parts. Tile systems, multi-part cassettes, seal subsystems, capsule lockups, high part count.
Usability & Error Resistance 10% Clear 4-letter BIP39 grids, low cognitive load, fewer steps, fewer opportunities for transcription mistakes. Word→index conversion steps, fiddly tile placement, multi-screw assembly, ambiguous recovery in degraded conditions.
Sovereign Ethos 10% Vendor-agnostic BIP39, minimal “ecosystem lock-in”, strong self-custody posture. “Managed” flows centered on seals, branded dependency, or artifact identity features.
Flexibility / Use-case Fit 5% Supports multiple strategies (multi-location, multi-copy, multisig/shares) without adding metadata. Over-specialization that forces extra metadata onto the artifact.
Cost / Deployability 5% Reasonable unit price enabling multiple independent backups. Premium pricing that reduces redundancy or distribution options.
Composite math (exact)
Composite = (Metadata×0.30) + (Robustness×0.25) + (Simplicity×0.15)
          + (Usability×0.10) + (Ethos×0.10) + (Flexibility×0.05) + (Cost×0.05)
Note: two devices can share the same rounded integer composite but still be ordered by the underlying decimal composite.

Final ranking

Composite scores below are shown to two decimals (weighted sum) and rounded (integer) for quick scanning. Each device name links to its deep-dive section; external links are embedded in each deep dive.

Rank Device Composite (exact) Composite (rounded)
1 Coinkite SEEDPLATE (24 + Tiny 12) 95.55 96
2 Shift Crypto (BitBox) Steelwallet 95.15 95
3 CRYPTOTAG Zeus Starter Kit 93.90 94
4 Coinplate Alpha 91.50 92
5 BitBox Steelwallet Pro 86.85 87
6 Trezor Keep Metal (20/24) 80.80 81
7 SeedHammer II plates 80.70 81
8 Keystone Tablet 75.55 76
9 HODLR Shield (12/24) 72.05 72
10 Cryptosteel Cassette Solo 71.00 71

Full score matrix (0–100 per criterion)

Device Metadata
30%
Robustness
25%
Simplicity
15%
Usability
10%
Ethos
10%
Flex
5%
Cost
5%
Composite
Coinkite SEEDPLATE 98979889949088 95.55
BitBox Steelwallet 98979689939286 95.15
CRYPTOTAG Zeus 97989586929075 93.90
Coinplate Alpha 88969490929284 91.50
Steelwallet Pro 80948887929570 86.85
Trezor Keep Metal 60948890859280 80.80
SeedHammer II plates 55949286959680 80.70
Keystone Tablet 60758486889086 75.55
HODLR Shield 30958888889278 72.05
Cryptosteel Cassette 45788285889078 71.00

Tier summary

Tier 1 — Clean plates (minimal artifact metadata; high survivability)

  • Coinkite SEEDPLATE — no seals, no serials, simple punch plate (details).
  • BitBox Steelwallet — Lopp-tested A-grade behavior in a simple two-plate form (details).
  • CRYPTOTAG Zeus — titanium survivability with a small usability/cost trade (details).
  • Coinplate Alpha — very strong physical construction; optional security labels are the main metadata caveat (details).

Tier 2 — Strong tools with explicit trade-offs (seals / metadata / specialization)

  • Steelwallet Pro — reusable; includes tamper-evident sticker as part of the closure model (details).
  • Trezor Keep Metal — robust; includes security seals in the standard workflow (details).
  • SeedHammer plates — extreme multisig capability, but descriptor + QR can be embedded onto the artifact by design (details).

Tier 3 — Dominated under the artifact-purity model (identity surfaces / weak modes / part complexity)

  • Keystone Tablet — tile systems introduce failure modes; Lopp tests show strong asymmetry by variant (details).
  • HODLR Shield — uniquely identified editions and uniquely numbered covers create linkability primitives (details).
  • Cryptosteel Cassette — crush weakness in Lopp tests plus seal subsystem and high part-count (details).

Device deep dives (all details)

Each section includes a scorecard, rationale, and inline links to official pages and test references.

1) Coinkite SEEDPLATE (24 Words + Tiny 12)

Composite: 95.55 (≈96) Profile: clean punch plate
CriterionScoreNotes
Artifact Metadata & Privacy (30%)98No serials; no enforced seals; no descriptor/QR on the plate. Minimal identity surface on the artifact (Coinkite SEEDPLATE).
Physical Robustness (25%)97Lopp’s Seedplate test shows no data loss under heat/corrosion/crush (review).
Mechanical Simplicity (15%)98Single plate; no tiles; no enclosure that can jam.
Usability & Error Resistance (10%)89Manual center-punch on a 4-letter BIP39 grid; straightforward but still manual.
Sovereign Ethos (10%)94Vendor-agnostic BIP39 backup with minimal “managed” workflow and no semantic bloat on metal.
Flexibility / Use-case Fit (5%)90Works for single-sig and as a replicated artifact across multi-location / multisig strategies.
Cost / Deployability (5%)88Low enough to deploy multiple copies (pricing).
Why it ranks #1
A near-maximal intersection of: (a) minimal metadata on the artifact, (b) Lopp-style survivability behavior for the punch-plate class, (c) extremely low mechanical failure surface (no tiles/rails/seals required), and (d) realistic deployability for redundancy.

2) Shift Crypto (BitBox) Steelwallet (non-Pro)

Composite: 95.15 (≈95) Profile: clean two-plate punch backup
CriterionScoreNotes
Artifact Metadata & Privacy (30%)98Plain plates with no enforced seals or identifiers (shop page).
Physical Robustness (25%)97Lopp review reports no data loss in heat/corrosion/crush for Steelwallet (review).
Mechanical Simplicity (15%)96Two plates and punch; minimal part-count compared to tile systems.
Usability & Error Resistance (10%)89Clear instruction flow and familiar 4-letter BIP39 pattern (features).
Sovereign Ethos (10%)93Vendor-agnostic seed backup, minimal workflow ceremony (overview).
Flexibility / Use-case Fit (5%)92Two-plate form is inherently redundancy-friendly; supports multi-copy / multi-location distribution.
Cost / Deployability (5%)86Moderate unit cost; still feasible for multiple independent backups (pricing).
Why it ranks #2 (near tie with #1)
Almost the same “clean plate” properties as SEEDPLATE, with a two-plate design and a similarly minimal metadata footprint. The spread is small and mostly driven by minor differences in simplicity and deployability.

3) CRYPTOTAG Zeus Starter Kit (titanium)

Composite: 93.90 (≈94) Profile: titanium survivability; index mapping
CriterionScoreNotes
Artifact Metadata & Privacy (30%)97No enforced seals/serials described; artifact is not designed around linkability (Lopp review).
Physical Robustness (25%)98Titanium and strong performance in Lopp’s heat/corrosion/crush testing (review).
Mechanical Simplicity (15%)95Simple plate workflow; minimal parts; no tile matrix.
Usability & Error Resistance (10%)86Word→index mapping adds cognitive steps versus 4-letter punch grids (see workflow in product docs).
Sovereign Ethos (10%)92BIP39-compatible across wallets; not tied to a coordinator or descriptor scheme.
Flexibility / Use-case Fit (5%)90Strong for long-term seed survivability; suited to multi-copy distribution.
Cost / Deployability (5%)75Premium titanium pricing can reduce redundancy per budget (pricing).
Primary trade-off
Zeus is physically apex, but the index-mapping workflow and price create the main “dominated” axis versus cheaper A-grade stainless punch plates.

4) Coinplate Alpha

Composite: 91.50 (≈92) Profile: ultra-thick bolted plates
CriterionScoreNotes
Artifact Metadata & Privacy (30%)88Plate is clean; kits often include tamper-evident “security labels” as a feature (example kit listing).
Physical Robustness (25%)96Lopp review documents strong performance; 5mm AISI 304 plates and bolts (review; specs).
Mechanical Simplicity (15%)94Two plates + bolts; no tile system. Slightly more hardware than single plates.
Usability & Error Resistance (10%)90Clear layout; bolted sandwich improves survivability while remaining readable (layout).
Sovereign Ethos (10%)92BIP39-first and vendor-agnostic; no descriptor/QR on artifact.
Flexibility / Use-case Fit (5%)92Supports replicated backups and multi-location storage; value packs exist (shop).
Cost / Deployability (5%)84Moderate price for robustness; better value than many premium titanium kits (pricing).
Key nuance
Coinplate Alpha is physically and mechanically strong; the primary penalty is the optional “security label” ecosystem (extra metadata surfaces) rather than the plates themselves.

5) BitBox Steelwallet Pro

Composite: 86.85 (≈87) Profile: reusable tile insert + casing
CriterionScoreNotes
Artifact Metadata & Privacy (30%)80Includes a tamper-evident sticker as part of the closure model (shop page). Some third-party reviews describe the sticker as numbered (Blocktrainer).
Physical Robustness (25%)94Thick stainless casing designed for fire/water/impact (specs). Not in Lopp’s dataset; robustness score reflects design/material expectations rather than a public destructive series.
Mechanical Simplicity (15%)88Tile + rail + casing introduces more failure points than a punch plate.
Usability & Error Resistance (10%)87Avoids punching errors but introduces tile handling complexity; reusable design is the main advantage.
Sovereign Ethos (10%)92Still vendor-agnostic BIP39 storage; no descriptor/QR on artifact.
Flexibility / Use-case Fit (5%)95High flexibility due to reusability (product description).
Cost / Deployability (5%)70Premium cost reduces easy multi-copy deployment (BitBox shop pricing list).
Why it beats most “capsule/tile” systems but not the top plates
Steelwallet Pro is well engineered and reusable; however, the tamper-sticker closure model and additional mechanical complexity keep it below the clean punch-plate cluster.

6) Trezor Keep Metal (20/24 variants)

Composite: 80.80 (≈81) Profile: robust kit + security seals
CriterionScoreNotes
Artifact Metadata & Privacy (30%)60Security seals are included as part of the standard kit (“What’s in the box” includes “Security seals”) (product page).
Physical Robustness (25%)94AISI 304 stainless with black surface treatment; marketed as waterproof and corrosion resistant (product details). Not in Lopp’s dataset.
Mechanical Simplicity (15%)88More assembly and enclosure mechanics than flat plates; still simpler than many tile cassettes.
Usability & Error Resistance (10%)90Four-letter entry system and guided kit approach (workflow).
Sovereign Ethos (10%)85BIP39/backup compatible across wallets, but positioned as a branded system within Trezor’s ecosystem pages.
Flexibility / Use-case Fit (5%)92Multiple word-length variants and compatibility claims (guide).
Cost / Deployability (5%)80Mid pricing; deployable in multiples, but less efficiently than cheaper plates.
Primary reason it ranks below the top tier
The default seal-centric kit model adds an extra metadata surface and increases dependency on “managed” storage rituals versus plain plates.

7) SeedHammer II plates (backup plates)

Composite: 80.70 (≈81) Profile: multisig descriptor on metal (by design)
CriterionScoreNotes
Artifact Metadata & Privacy (30%)55SeedHammer plates can embed descriptor parts and QR codes on metal to enable fast recovery (metal plates article), which is structurally metadata-rich compared to seed-only plates. Seed-only mode exists (FAQ).
Physical Robustness (25%)94316L “marine grade” stainless and thick plates are chosen for harsh conditions (material rationale). Not in Lopp’s dataset.
Mechanical Simplicity (15%)92The plate artifact is simple; complexity is primarily in the backup format and optional QR use.
Usability & Error Resistance (10%)86High speed recovery by scanning QR shares into coordinators like Sparrow is a design goal (QR discussion).
Sovereign Ethos (10%)95Strong multisig focus; avoids dependence on digital descriptor storage by embedding descriptor parts in steel (scheme).
Flexibility / Use-case Fit (5%)96Designed around quorum recovery in multisig setups (partitioning).
Cost / Deployability (5%)80Plates themselves are deployable; full workflow often assumes access to the SeedHammer engraver stack.
Core trade-off: capability vs artifact purity
SeedHammer solves descriptor coordination on steel, which is powerful for multisig, but inherently raises the semantic/metadata load on each physical artifact. In a strict “seed-only, low metadata” model, that cost is unavoidable.

8) Keystone Tablet (Tablet / Tablet Plus / Tablet Punch family)

Composite: 75.55 (≈76) Profile: tile systems + screws; variant-dependent survivability
CriterionScoreNotes
Artifact Metadata & Privacy (30%)60Includes “security seal stickers” / “tamper-proof stickers” in standard box contents (Tablet; Tablet Plus).
Physical Robustness (25%)75Variant-dependent: Tablet Plus and Punch have different Lopp grades (see master table and Round V).
Mechanical Simplicity (15%)84Tile systems + multiple screws increase failure surface compared to punch plates.
Usability & Error Resistance (10%)86Readable tiles, but assembly and long-term handling are more error-prone than punch grids.
Sovereign Ethos (10%)88Wallet-agnostic backup; not descriptor-heavy by default.
Flexibility / Use-case Fit (5%)90Supports multiple word lengths and setups; reusability depends on variant (Plus).
Cost / Deployability (5%)86Often priced to enable multiple deployments, but with survivability caveats by variant.
Variant note (important)
Lopp’s Round V shows asymmetry: some Keystone variants score well in corrosion/crush but fail more dramatically in heat (tile behavior), while others show different weaknesses. This “single-mode failure” pattern is why the family ranks below the simpler A-grade punch plates.

9) HODLR Shield (12/24 variants)

Composite: 72.05 (≈72) Profile: high physical protection + explicit identity surfaces
CriterionScoreNotes
Artifact Metadata & Privacy (30%)30Bitcoin Edition is “laser-marked with the last mined Bitcoin block … and a unique serial number” (official description). Shield variants can include “uniquely numbered tamper-evident covers” (Stealth 24).
Physical Robustness (25%)95Engineered for high physical protection; marketing emphasizes pressure-tightening behavior and high resistance (Stealth page).
Mechanical Simplicity (15%)88More moving pieces and sealing elements than a simple plate.
Usability & Error Resistance (10%)88Four-letter marking workflow is familiar; packaging includes aids and protocols (how it works).
Sovereign Ethos (10%)88Self-custody aligned, but “collector artifact” identity features run against a strict unlinkability posture.
Flexibility / Use-case Fit (5%)92Supports multiple backup setups including multi-share protocols in their “backup protocol” guides (Stealth page).
Cost / Deployability (5%)78Premium pricing can reduce multi-copy distribution (see pricing on product pages).
Why it ranks low despite strong physical engineering
The identity surface is structural: unique serial numbers, time-stamped block engravings, and uniquely numbered covers convert the object into a linkability primitive. Under an artifact-purity model, that alone forces a major penalty that robustness cannot “buy back.”

10) Cryptosteel Cassette Solo

Composite: 71.00 (≈71) Profile: cassette tiles + security seals; crush weakness
CriterionScoreNotes
Artifact Metadata & Privacy (30%)45Cassette Solo includes “four tamper-evident security seals with composite wire” as part of the set (official). PSW-97 style seals are commonly numbered (PSW-97).
Physical Robustness (25%)78Lopp grades the Cassette as B overall with a D in crush (critical) (master table; review).
Mechanical Simplicity (15%)82Tile cassette + seals introduces many small parts and failure points.
Usability & Error Resistance (10%)85Readable 4-letter tiles, but assembly and maintenance are more tedious than punch plates (how it works).
Sovereign Ethos (10%)88Vendor-agnostic BIP39 approach; no descriptor/QR on artifact by default.
Flexibility / Use-case Fit (5%)90Supports multiple wallets and setups; still dominated by simpler plates under this model.
Cost / Deployability (5%)78Mid-to-premium price without corresponding crush survivability compared to A-grade plates.
Core failure mode
The Cassette’s crush weakness in Lopp’s testing is decisive. Under “rubble / collapse / press” scenarios, tile-based systems are more likely to deform, jam, or lose ordering integrity than a single punched plate.